Every patch window is a bet.
We build the software that settles it.
Zurlux builds reliability tooling for enterprise infrastructure teams. Our first product, PatchMortem, tells you why a patch failed, rolls it back before the window closes, and leaves an audit trail an auditor can actually read.
One change window, start to finish.
Change CHG0044182 — 212 hosts, a live patch failure, diagnosed and rolled back before the window closed.
Diagnosis, not alerts.
Monitoring tells you something broke. Our products tell you what broke it, what to do, and then do it — with a record of every decision.
Root cause, before the window closes
Agent signals are matched against 215 documented failure patterns across seven platforms — anchored on the error code and failing component, so you get a specific cause, not a category.
See how it worksRegulated and run hard
Banking, insurance, healthcare, manufacturing, and the MSPs who patch on their behalf. Environments where a missed rollback becomes a compliance finding.
Banking & BFSISmall, senior, hands on
Engineers who have run enterprise patching estates. Every design decision is checked against how the work is actually done at 2 a.m.
Who we areTransparent pricing, in INR.
30-day free trial on all plans. Available on AWS Marketplace against your committed EDP spend.
- Semantic patch-failure classification
- Automated rollback execution
- HMAC audit trail · 90-day retention
- SCCM, Intune, ManageEngine
- Everything in Starter
- Predictive failure intelligence
- Compliance reporting · RBI, PCI-DSS, SEBI
- vSphere + Kubernetes support
- ServiceNow / Jira sync · RBAC
- Everything in Enterprise
- On-premise deployment option
- Custom compliance frameworks
- SLA-backed uptime · dedicated engineering
Environments where a missed rollback is a finding.
Banking & BFSI
Aligned to RBI IT Framework 2023, SEBI and IRDAI evidence requirements.
Insurance
Change windows on regulated policy and claims infrastructure.
Healthcare
Uptime-critical estates where an unpatched host is a live risk.
MSPs
Managed service providers patching many estates on clients' behalf.
Run PatchMortem against your own environment.
A 30-minute session on your actual patch-management setup — no slides, no vendor pitch. We'd rather show you a rollback on your stack than tell you about ours.
Questions procurement will ask.
When a patch fails during a change window, it identifies the root cause by matching the failure against 215 documented patterns, executes the correct rollback where that is safe, and writes an append-only audit record of every decision. It reacts to your patch schedule — it does not set one.
Both. Agentless integrates via webhook from your existing tool (Intune, SCCM, ManageEngine) and deploys in about a day. The agent captures raw system-log signal directly from the endpoint for higher-confidence classification and the full set of 60+ rollback methods. Most BFSI estates start agentless.
All data is stored and processed in AWS ap-south-1 (Mumbai, India). The agent is code-signed and outbound-only — it opens no inbound connections to your endpoints. Sub-processors are disclosed in the DPA under the DPDP Act 2023.
Every detection, classification, approval and rollback is written to an append-only, HMAC-SHA256 cryptographically chained log, built for RBI IT Framework Section 4.2. Tamper with one record and the chain breaks. Exports are available for RBI, PCI-DSS, SEBI and IRDAI.
SOC 2 Type I is in progress. The underlying controls are already running — data residency in ap-south-1, code-signed outbound-only agent, append-only audit chain, least-privilege access, SSO and RBAC — and we'll share the report when the audit completes rather than imply a certification we don't yet hold.